Be able to pick the correct risk response for a scenario, order treatment steps, and classify controls. The key is recognizing that residual risk above appetite requires explicit acceptance by the accountable owner, not silent continuation.
Start practicing
Risk Response and Mitigation — choose a session length
Free · No account required
Domain overview
This domain covers selecting, implementing, and validating risk responses—mitigation, transfer, avoidance, and acceptance—and tracking residual risk against appetite. Questions test sequencing control implementation, classifying response types, and judging whether proceeding above appetite with monitoring is acceptable. Expect scenario-based items tied to risk register updates and control ownership.
Exam objectives
Classifying responses as mitigate, transfer, avoid, or accept for a given scenario
Sequencing risk treatment steps: assess, select response, implement controls, monitor residual risk
Distinguishing preventive, detective, and corrective controls and their placement in the process
Determining whether residual risk above appetite can proceed with monitoring and approval
Treating risk acceptance as a failure of response rather than a valid, documented decision with owner sign-off
Confusing risk transfer (insurance, contracts) with risk mitigation, which reduces likelihood or impact directly
Skipping control effectiveness testing and assuming implementation equals reduced residual risk
Click any question to see the full explanation and answer options, or start a focused practice session above.
After implementing a new web application, the risk owner reports that the residual risk level is still above the risk appetite. Which of the following should be the risk practitioner's FIRST action?
2A multinational organization is implementing a risk mitigation strategy for a critical system. The business impact analysis shows that downtime costs are extremely high. Which risk response strategy is MOST appropriate for this scenario?
3An organization decides to outsource its data center operations to a third party. This is an example of which risk response?
4During a review, a risk practitioner discovers that a key control for a high-risk process is not operating effectively. The risk owner is reluctant to invest in additional controls due to budget constraints. What should the risk practitioner do FIRST?
5A company has implemented a risk mitigation plan that includes technical controls. However, six months later, the residual risk is still higher than expected. The risk practitioner suspects that the controls are not being followed. Which of the following is the BEST approach to verify this?
6Which THREE of the following are key components of an effective risk treatment plan?
7You are a risk practitioner at a financial institution that is migrating its core banking system to a cloud provider. The migration plan includes a phased approach, with the first phase moving non-critical applications. However, during the second phase (moving customer-facing applications), the cloud provider experiences a major outage that lasts 6 hours. The outage was caused by a misconfiguration in the provider's network. The institution had conducted a risk assessment and identified cloud provider downtime as a risk, but the treatment plan only included a service level agreement (SLA) with financial penalties. The SLA does not cover the reputational damage and loss of customer trust. The risk register shows that the residual risk level was marked as 'low' before the incident. After the incident, senior management is demanding a review. Which of the following is the MOST appropriate action for the risk practitioner to take?
8Based on the risk register exhibit, which of the following is the MOST appropriate risk response for R-0042?
9A global manufacturing company is implementing a new ERP system across multiple regions. The project manager has identified a risk that data migration from legacy systems may cause data corruption, leading to production delays. The risk owner proposes conducting a full data reconciliation after migration. However, the IT director argues that this would be too time-consuming and suggests only sampling data for verification. The risk manager must decide on the risk response. The project timeline is tight, and the company has a low tolerance for data integrity issues. Which of the following is the BEST course of action?
10Order the steps for implementing a risk treatment plan.
11Sequence the steps for implementing a new control based on risk assessment findings.
12Put the steps for performing a control self-assessment (CSA) in order.
13Match each risk response strategy to its definition.
14Match each risk management term to its definition.
15A company has identified a critical vulnerability in a legacy application that cannot be patched immediately. The application is used by a small number of users and supports a non-critical business process. Which of the following is the MOST appropriate risk response strategy?
16During a risk assessment, the risk owner identifies that the residual risk level is higher than the risk appetite. Which of the following actions should the risk owner take FIRST?
17An organization's security team recommends implementing a web application firewall (WAF) to protect against SQL injection attacks. The risk manager evaluates the cost of the WAF and the likelihood of a successful attack. This evaluation is BEST described as:
18A company is implementing a new cloud-based customer relationship management (CRM) system. The risk manager has identified that the vendor's security controls may not meet the company's requirements. Which of the following is the BEST way to address this risk?
19A risk assessment reveals that a data center is located in a flood-prone area. The organization decides to build a secondary data center in a different region and replicate critical data between both sites. This is an example of which risk response?
20After implementing a set of controls, the risk owner calculates the residual risk and finds it is still above the risk tolerance. However, the cost to further reduce the risk exceeds the potential loss. What is the MOST appropriate next step?
21A bank implements a new transaction monitoring system to detect fraudulent activities. After six months, the system has a high false positive rate, causing analysts to miss real threats. Which of the following is the BEST way to address this risk?
22Which TWO of the following are examples of risk mitigation controls?
23Which THREE of the following are key considerations when selecting a risk response option?
24A security team identifies a critical vulnerability in a web application that cannot be patched immediately. They deploy a web application firewall (WAF) to block exploitation attempts. This is an example of:
25An organization purchases cyber insurance to cover potential losses from data breaches. This is an example of:
26After a risk assessment, a company decides to stop using a third-party service that has high residual risk. This is an example of:
27A risk assessment reveals that a legacy system has a high likelihood of failure. The system is critical and cannot be replaced immediately. The company decides to implement manual overrides and additional monitoring. This is an example of:
28An organization has a policy requiring all sensitive data to be encrypted at rest. During an audit, it is found that encryption keys are stored in plaintext on the same server. Which risk response is MOST appropriate?
29A company faces a risk of data loss due to untrained staff. They implement mandatory training and quarterly phishing simulations. This is:
30A risk assessment identifies that a legacy system has a high risk of failure with no available vendor support. The organization decides to decommission the system and migrate to a modern platform. This is:
31After implementing multiple controls, the residual risk for a new product launch is still slightly above the risk appetite. The risk manager decides to proceed with the launch and monitor the risks regularly. This is:
32Which TWO of the following are examples of risk transfer? (Select TWO.)
33Which TWO of the following are examples of risk avoidance? (Select TWO.)
34Which THREE of the following are examples of risk mitigation controls? (Select THREE.)
35Based on the exhibit, what is the primary risk response strategy demonstrated by this firewall rule?
36Based on the exhibit, which risk is most likely present and what is the most appropriate risk response?
37A global company uses a critical third-party vendor for data processing. The inherent risk is high, but the vendor has implemented robust controls. However, due to recent geopolitical instability, the vendor's physical location is at risk. The risk owner recommends purchasing a business continuity insurance policy. Which risk response is being applied?
38A new privacy regulation requires that all personal data be encrypted at rest. The current systems lack encryption. The cost to implement encryption is moderate, and the risk of non-compliance is high. Which risk response is most appropriate?
39After implementing security controls, a risk assessment shows a residual risk of data exfiltration with a probability of 5% and potential loss of $10 million. The organization's risk appetite allows a maximum acceptable risk level of 3% probability for such impact. The cost of further mitigation is $1 million. What is the best risk response?
40An employee with access to sensitive financial data has been observed accessing systems outside of normal working hours and exhibiting erratic behavior. The IT risk manager suspects insider threat. What is the most appropriate risk response?
41A recent security assessment identified that a critical web application is vulnerable to SQL injection due to unpatched software. The vendor has released a security patch. Which risk response is most appropriate?
42An organization uses a legacy system that cannot be patched because the vendor is defunct. The system supports a core business function. The risk assessment shows a high likelihood of exploitation and high impact. The board has decided to keep the system operational due to its criticality. Which risk response should the risk manager recommend?
43A risk assessment reveals that the cost of implementing a control ($500k) exceeds the annualized loss expectancy (ALE) of $300k. The risk is currently within the organization's risk appetite. What is the appropriate risk response?
44For a risk with very low likelihood and low impact, what is the typical risk response?
45A third-party vendor's security assessment reveals multiple high-risk findings related to data handling. The vendor is unwilling to remediate, citing cost. The vendor contract includes a clause that requires adherence to security standards. The organization's risk appetite for third-party risk is low. What is the most appropriate risk response?
46A company has a critical production system with a known vulnerability. Due to the system's age, the vendor no longer supports it. The company decides to implement network segmentation and purchase cyber insurance to cover potential losses. Which TWO risk response options are they applying?
47A risk assessment identifies a high likelihood of a data breach due to insecure APIs. The risk team proposes disabling the APIs until they are secured, implementing a WAF, and purchasing breach insurance. Which THREE risk response options are being considered?
48Which THREE of the following are key components of an effective risk response plan?
49A small e-commerce company has identified a high-risk vulnerability in its payment processing system that could expose customer credit card data. The IT team recommends immediately patching the system, but the patch requires a 4-hour downtime during peak sales hours. The risk manager proposes accepting the risk until the next scheduled maintenance window in two weeks. The CEO is concerned about potential fines from PCI DSS non-compliance. What is the BEST course of action?
50A multinational corporation has adopted a risk mitigation strategy for its key suppliers by requiring them to maintain ISO 27001 certification. During an audit, the risk manager discovers that one critical supplier lost its certification six months ago but did not report it, as contractually required. The supplier still has adequate security controls in place, and the relationship is strategically important. The CEO wants to avoid contract termination. What is the MOST appropriate risk response?
51A financial institution is implementing a new online banking platform. The risk assessment identified that the platform will handle sensitive customer data and must comply with GDPR and local banking regulations. The project team proposes encrypting all data at rest and in transit, implementing multi-factor authentication (MFA), and conducting quarterly penetration tests. However, the risk owner is concerned about the residual risk of a sophisticated phishing attack that could bypass MFA. The board has a low risk appetite. What is the BEST way to address this residual risk?
52A healthcare organization is migrating its electronic health records (EHR) system to a cloud provider. The risk assessment shows that the cloud provider has strong security certifications (e.g., SOC 2 Type II, ISO 27001). However, the organization's legal team is concerned about data sovereignty laws that require patient data to remain within the country. The cloud provider's data centers are located in three regions: one in-country, and two outside. The project manager proposes using only the in-country data center. The IT director warns that this will increase latency and reduce redundancy. The risk manager must propose a response. Which is the BEST option?
53A risk practitioner is reviewing the organization's risk response strategies for a high-value asset. Which TWO of the following are examples of risk mitigation techniques? (Choose two.)
54A financial services firm has a critical web application that must remain available 24/7. The risk assessment indicates that a distributed denial-of-service (DDoS) attack could cause significant downtime. The risk owner decides to implement a cloud-based DDoS mitigation service that scrubs traffic before it reaches the application. Which risk response strategy does this represent?
55A multinational corporation has a risk register entry for a potential data breach of customer information. The risk owner has decided to purchase cyber insurance to cover financial losses from a breach. Which of the following BEST describes the residual risk after this risk response?
56A financial services company's risk register shows that a critical vulnerability in its online banking application has a high likelihood of exploitation and a high impact. The risk owner decides to implement a web application firewall (WAF) and conduct monthly penetration tests. Which risk response strategy is being applied?
57A financial services firm operates a high-volume transaction processing platform. During a risk assessment, the risk owner determines that the residual risk of database corruption exceeds the risk appetite. The database vendor offers a patch that reduces the vulnerability but requires a 12-hour outage. Business stakeholders refuse the outage. The risk practitioner is asked to recommend a risk response that aligns with the risk appetite without disrupting operations. Which of the following is the BEST recommendation?
58A financial services firm has identified that its primary data center is located in a region prone to hurricanes. The risk manager proposes purchasing business interruption insurance to cover potential losses from a catastrophic event. Which risk response strategy does this represent?
59A financial services firm has a risk register entry for a core banking application with an inherent risk score of 9 (high). The risk owner implements a new database activity monitoring tool and role-based access reviews. After implementation, the residual risk score is reassessed at 6 (medium). The risk owner now wants to formally document that the risk has been reduced to an acceptable level. Which action should the risk practitioner recommend NEXT?
60A healthcare organization is required by regulation to retain patient records for seven years. The risk manager is evaluating a new cloud storage solution that offers encryption at rest but stores data in multiple jurisdictions. Which of the following is the MOST critical risk consideration when selecting this solution?
61A hospital's risk team has documented that its infusion pump fleet runs an unsupported operating system, creating a high risk of compromise. Replacing the pumps requires capital approval that will take 18 months, and the pumps cannot be taken offline in the interim. Which risk response is MOST appropriate for the risk practitioner to recommend?
62A multinational corporation is deploying a new IoT-based inventory management system across its warehouses. The risk practitioner identifies that the IoT devices use default administrative credentials and unencrypted communication protocols. The vendor states that a firmware update to address these issues will not be available for six months. The business cannot delay the deployment due to competitive pressures. Which risk response strategy is MOST appropriate in this situation?
63A financial services firm has a risk register entry for a critical trading application. The business owner proposes adding a redundant data center to reduce downtime risk. The risk practitioner notes that the redundancy will cost $2 million annually and reduce expected annual loss from $3 million to $500,000. Which factor is MOST important for the risk practitioner to evaluate before recommending approval?
64A retail company has a risk register that includes a risk of inventory shrinkage due to employee theft. The risk manager decides to implement a new surveillance system and conduct background checks on all new hires. Which risk response strategy is being applied?
65A financial services firm has determined that a critical trading application cannot be patched for a known remote code execution vulnerability because the vendor no longer supports the platform. The risk manager decides to deploy a web application firewall (WAF) with virtual patching and network segmentation to isolate the application from the internal network. Which risk response strategy does this represent?
66A retail company is launching a new mobile payment application. The risk practitioner is identifying risk response options for the risk of payment fraud. Which TWO of the following are examples of risk mitigation controls? (Choose two.)
67A risk practitioner at a financial services firm is updating the risk register. For a risk involving unauthorized access to the customer database, the risk owner has decided to purchase a cyber liability insurance policy that covers breach-related costs. Which risk response option has the risk owner selected?
68A retail company's risk register shows that a point-of-sale system vulnerability has a high likelihood and high impact. The IT team proposes applying a vendor patch, but the patch has not been tested with the custom payment application. Which risk response strategy is being considered?
69A software development company is launching a new mobile application that will collect user location data. The risk manager identifies that the data collection could violate privacy regulations if not properly disclosed. The legal team recommends updating the privacy policy and obtaining explicit user consent. Which risk response strategy is this?
70A multinational corporation is implementing a risk treatment plan for a critical vendor that has poor security controls. The risk practitioner has recommended contract renegotiation to include security requirements, but the vendor refuses. The business unit insists on continuing the relationship due to cost savings. The risk practitioner's next step should be to:
71A healthcare organization's risk register shows that a critical server lacks vendor support and has a high inherent risk of failure. The risk owner proposes to implement redundant hardware and a failover cluster. The cost of the redundancy is $200,000, while the estimated annual loss from failure is $150,000. Which factor is MOST important for the risk practitioner to consider when evaluating this proposed risk response?
72A hospital's risk register identifies that a critical medical imaging server runs an unsupported operating system, creating a high likelihood of exploitation. The vendor will not release a patch, and the server cannot be taken offline because it supports active patient care. The CISO asks the risk practitioner to reduce the likelihood of exploitation without disrupting imaging services. Which risk response is MOST appropriate?
73A risk practitioner is reviewing the organization's risk register and notes that a critical web application has a high inherent risk of SQL injection. The development team proposes implementing a web application firewall (WAF) with virtual patching. The risk practitioner's primary responsibility in this scenario is to:
74A multinational corporation is developing a risk treatment plan for a newly identified risk: a critical vendor's financial instability could disrupt the supply chain. The risk manager is considering several options. Which TWO of the following are examples of risk mitigation controls that directly reduce the likelihood or impact of this risk? (Choose two.)
75A risk manager is reviewing the organization's risk treatment plan for a critical web application. The plan includes implementing a web application firewall (WAF), conducting regular penetration tests, and purchasing cyber insurance. The risk manager notes that the residual risk after these treatments is still above the risk appetite. According to CRISC, what should the risk manager do NEXT?
76A financial services firm is deploying a new trading platform. The risk committee has approved a risk treatment plan that includes a requirement to implement a circuit breaker that halts trading if losses exceed a predefined threshold. The project manager asks the risk practitioner to verify that the control is designed effectively before go-live. Which activity BEST validates the design of this risk mitigation control?
77A retail company has identified that its point-of-sale (POS) terminals are running an outdated operating system that no longer receives security patches. The risk practitioner recommends upgrading the terminals to a supported OS. The cost of the upgrade is $500,000, while the estimated annual loss from a potential breach is $2,000,000 with a 30% likelihood. Which risk response strategy is being recommended?
78A retail company is launching a new e-commerce platform. The risk management team has identified that the platform's payment gateway integration could be exploited to intercept customer credit card data. The team proposes several controls. Which of the following are examples of risk mitigation controls? (Choose two.)
79A multinational bank has a risk appetite that allows for a maximum of 5% downtime for its online banking platform per quarter. The platform currently experiences 8% downtime due to frequent distributed denial-of-service (DDoS) attacks. The risk owner proposes investing in a cloud-based DDoS mitigation service. Which of the following should be the risk practitioner's PRIMARY consideration when evaluating this proposed risk response?
80A software development company uses a third-party cloud provider to host its source code repositories. The risk practitioner discovers that the provider's contract does not include a right-to-audit clause. The provider has a strong security reputation but is unwilling to add the clause. The company's risk appetite for third-party risk is low. Which action should the risk practitioner recommend FIRST?
81A risk practitioner is reviewing the organization's risk response plan for a database containing personally identifiable information (PII). The plan states that the database will be encrypted at rest, access will be restricted to authorized personnel, and regular backups will be performed. Which risk response strategy is being applied?
82A retail company is implementing a new point-of-sale (POS) system that accepts contactless payments. The risk practitioner identifies that the existing network segmentation between the POS environment and the corporate network is inadequate. The risk committee asks for compensating controls that will reduce the risk of lateral movement from a compromised POS terminal. Which TWO of the following controls BEST address this risk? (Choose two.)
83A healthcare organization has identified that its patient portal has a vulnerability that could expose sensitive data. The risk owner decides to implement multifactor authentication (MFA) for all users. After implementation, the risk practitioner conducts a follow-up assessment and finds that some users are sharing credentials, potentially bypassing MFA. The risk practitioner should FIRST:
84A software company has identified that a critical third-party library used in its product has a known remote code execution vulnerability. The vendor has not released a patch, and the product is used by customers who cannot accept downtime. The risk practitioner recommends isolating the library's functionality in a sandboxed process with restricted permissions. Which risk response strategy does this represent?
85A multinational corporation has a risk register entry for a supplier that provides critical components. The supplier has a history of financial instability, and the risk of supply chain disruption is high. The risk owner decides to dual-source the components from a second supplier. Which risk response strategy does this represent, and what is the primary benefit?
86A multinational bank is subject to GDPR and local data protection laws. The risk practitioner is reviewing a risk treatment plan for a new customer analytics platform that will process personal data across three jurisdictions. The plan proposes to rely on the vendor's standard contractual clauses (SCCs) as the primary control for cross-border data transfers. Which factor is MOST important for the risk practitioner to evaluate when assessing the adequacy of this risk response?
87A risk manager is reviewing the risk treatment plan for a new mobile banking application. The plan includes implementing multi-factor authentication (MFA) and conducting regular vulnerability scans. The risk manager wants to ensure that the controls are operating effectively. Which of the following should be performed to verify the effectiveness of the controls?
88A software development company identifies that developers are storing API keys in plaintext within source code repositories. The risk practitioner proposes a risk treatment plan that includes implementing a secrets management solution and rotating all exposed keys. The Chief Technology Officer asks how the risk practitioner will confirm that the treatment plan is reducing the risk over time. Which metric is MOST appropriate for monitoring the effectiveness of this risk response?
89A risk practitioner is working with the IT team to design controls for a new cloud-based human resources system. The team proposes using encryption for data at rest and in transit, role-based access controls, and regular backups. The risk practitioner notes that these controls address confidentiality, integrity, and availability. Which of the following should the risk practitioner recommend to ensure the controls remain effective over time?
90A small retail company has determined that the risk of a point-of-sale (POS) system malware infection is high. The company decides to implement a whitelisting solution that only allows approved applications to run on POS terminals. This is an example of which risk response?
91A financial services firm's risk register shows that a critical trading application has a high inherent risk of unauthorized access. The risk owner decides to implement multifactor authentication (MFA) and role-based access controls (RBAC). After implementation, the residual risk score decreases but remains above the risk appetite. Which of the following should the risk practitioner recommend NEXT?
92A multinational corporation is deploying a new enterprise resource planning (ERP) system across 30 countries. The risk manager identifies that data residency laws in several countries require customer data to remain within national borders. The project team proposes using a single global cloud region for simplicity. Which risk response strategy is MOST appropriate for the risk manager to recommend?
93A healthcare organization is required by law to retain patient records for seven years. The IT department proposes storing backups on tapes that are kept in an on-site vault. The risk manager notes that the on-site vault is in a flood zone. Which risk response strategy is being applied if the organization decides to move the tapes to a secure off-site facility in a different geographic region?
94A software development company is adopting a DevOps model and wants to accelerate deployments. The risk manager is concerned that rapid changes could introduce security vulnerabilities. The team proposes implementing automated security testing in the CI/CD pipeline. Which of the following BEST describes the risk response strategy being applied?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to pick the correct risk response for a scenario, order treatment steps, and classify controls. The key is recognizing that residual risk above appetite requires explicit acceptance by the accountable owner, not silent continuation.
The Courseiva CRISC question bank contains 94 questions in the Risk Response and Mitigation domain, covering the 16% of the exam attributed to this domain in the official ISACA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Risk Response and Mitigation domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included